Junglewise Threat Intelligence

CVE-2026-56037: Themify Themify Popup PHP object injection

CVE-2026-56037 · Severity: high · CVSS 8.8 · Published 2026-07-02

Vendors: Themify.

Executive brief

Themify Popup, a WordPress plugin used to create and manage promotional popups, contains a security flaw that allows authenticated users to perform PHP Object Injection. If exploited, an attacker could potentially execute unauthorized code, access sensitive database information, or disrupt the website's availability. This could lead to a full site takeover or significant data theft depending on the server configuration.

Technical details

The Themify Popup plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.4.3. The vulnerability stems from the deserialization of untrusted data (CWE-502) without proper validation. An attacker with 'Contributor' level privileges or higher can exploit this to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present on the system, this can lead to remote code execution, SQL injection, or file system traversal. The issue is resolved in version 1.4.4.

Affected products

  • Themify Themify Popup <= 1.4.3

Timeline

  • 2025-07-16: other: Vulnerability reported by researcher 0xd4rk5id3
  • 2026-06-23: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published to NVD dataset

References